CVE-2014-0179
Summary
| CVE | CVE-2014-0179 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-08-03 18:55:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompareCPU or (2) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this issue was SPLIT per ADT3 due to different affected versions of some vectors. CVE-2014-5177 is used for other API methods. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:L/AC:M/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Opensuse | Opensuse | 12.3 | All | All | All |
| Operating System | Opensuse | Opensuse | 13.1 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
| Application | Redhat | Enterprise Virtualization | 3.0 | All | All | All |
| Application | Redhat | Libvirt | 0.10.0 | All | All | All |
| Application | Redhat | Libvirt | 0.10.1 | All | All | All |
| Application | Redhat | Libvirt | 0.10.2 | All | All | All |
| Application | Redhat | Libvirt | 0.10.2.1 | All | All | All |
| Application | Redhat | Libvirt | 0.10.2.2 | All | All | All |
| Application | Redhat | Libvirt | 0.10.2.3 | All | All | All |
| Application | Redhat | Libvirt | 0.10.2.4 | All | All | All |
| Application | Redhat | Libvirt | 0.10.2.5 | All | All | All |
| Application | Redhat | Libvirt | 0.10.2.6 | All | All | All |
| Application | Redhat | Libvirt | 0.10.2.7 | All | All | All |
| Application | Redhat | Libvirt | 0.10.2.8 | All | All | All |
| Application | Redhat | Libvirt | 0.7.5 | All | All | All |
| Application | Redhat | Libvirt | 0.7.6 | All | All | All |
| Application | Redhat | Libvirt | 0.7.7 | All | All | All |
| Application | Redhat | Libvirt | 0.8.0 | All | All | All |
| Application | Redhat | Libvirt | 0.8.1 | All | All | All |
| Application | Redhat | Libvirt | 0.8.2 | All | All | All |
| Application | Redhat | Libvirt | 0.8.3 | All | All | All |
| Application | Redhat | Libvirt | 0.8.4 | All | All | All |
| Application | Redhat | Libvirt | 0.8.5 | All | All | All |
| Application | Redhat | Libvirt | 0.8.6 | All | All | All |
| Application | Redhat | Libvirt | 0.8.7 | All | All | All |
| Application | Redhat | Libvirt | 0.8.8 | All | All | All |
| Application | Redhat | Libvirt | 0.9.0 | All | All | All |
| Application | Redhat | Libvirt | 0.9.1 | All | All | All |
| Application | Redhat | Libvirt | 0.9.10 | All | All | All |
| Application | Redhat | Libvirt | 0.9.11 | All | All | All |
| Application | Redhat | Libvirt | 0.9.11.1 | All | All | All |
| Application | Redhat | Libvirt | 0.9.11.2 | All | All | All |
| Application | Redhat | Libvirt | 0.9.11.3 | All | All | All |
| Application | Redhat | Libvirt | 0.9.11.4 | All | All | All |
| Application | Redhat | Libvirt | 0.9.11.5 | All | All | All |
| Application | Redhat | Libvirt | 0.9.11.6 | All | All | All |
| Application | Redhat | Libvirt | 0.9.11.7 | All | All | All |
| Application | Redhat | Libvirt | 0.9.11.8 | All | All | All |
| Application | Redhat | Libvirt | 0.9.12 | All | All | All |
| Application | Redhat | Libvirt | 0.9.13 | All | All | All |
| Application | Redhat | Libvirt | 0.9.2 | All | All | All |
| Application | Redhat | Libvirt | 0.9.3 | All | All | All |
| Application | Redhat | Libvirt | 0.9.4 | All | All | All |
| Application | Redhat | Libvirt | 0.9.5 | All | All | All |
| Application | Redhat | Libvirt | 0.9.6 | All | All | All |
| Application | Redhat | Libvirt | 0.9.6.1 | All | All | All |
| Application | Redhat | Libvirt | 0.9.6.2 | All | All | All |
| Application | Redhat | Libvirt | 0.9.6.3 | All | All | All |
| Application | Redhat | Libvirt | 0.9.7 | All | All | All |
| Application | Redhat | Libvirt | 0.9.8 | All | All | All |
| Application | Redhat | Libvirt | 0.9.9 | All | All | All |
| Application | Redhat | Libvirt | 1.0.0 | All | All | All |
| Application | Redhat | Libvirt | 1.0.1 | All | All | All |
| Application | Redhat | Libvirt | 1.0.2 | All | All | All |
| Application | Redhat | Libvirt | 1.0.3 | All | All | All |
| Application | Redhat | Libvirt | 1.0.4 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5.1 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5.2 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5.3 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5.4 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5.5 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5.6 | All | All | All |
| Application | Redhat | Libvirt | 1.0.6 | All | All | All |
| Application | Redhat | Libvirt | 1.1.0 | All | All | All |
| Application | Redhat | Libvirt | 1.1.1 | All | All | All |
| Application | Redhat | Libvirt | 1.1.2 | All | All | All |
| Application | Redhat | Libvirt | 1.1.3 | All | All | All |
| Application | Redhat | Libvirt | 1.1.4 | All | All | All |
| Application | Redhat | Libvirt | 1.2.0 | All | All | All |
| Application | Redhat | Libvirt | 1.2.1 | All | All | All |
| Application | Redhat | Libvirt | 1.2.2 | All | All | All |
| Application | Redhat | Libvirt | 1.2.3 | All | All | All |
| Application | Redhat | Libvirt | 1.2.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory SA60895 - Gentoo update for libvirt - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo Linux Documentation -- libvirt: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Libvirt Security Notice: LSN-2014-0003 | af854a3a-2127-422b-91ae-364da2661108 | security.libvirt.org | Patch, Vendor Advisory |
| libvirt: Releases | af854a3a-2127-422b-91ae-364da2661108 | libvirt.org | |
| USN-2366-1: libvirt vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Debian -- Security Information -- DSA-3038-1 libvirt | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| openSUSE-SU-2014:0650-1: moderate: libvirt: Fixed unsafe parsing of XML | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| openSUSE-SU-2014:0674-1: moderate: libvirt: Fix migration with QEMU 1.6 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| access.redhat.com | CVE-2014-0179 | MITRE | access.redhat.com | |
| Bug 1088290 – CVE-2014-0179 CVE-2014-5177 libvirt: unsafe parsing of XML documents allows libvirt DoS and/or arbitrary file read | MITRE | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.